VPNs

Google Play shows a data-safety declaration one app at a time. Here are 5 VPNs side by side, so the differences are visible rather than remembered. Categories none of them declares are hidden.

A VPN carries every packet your phone sends, so this is the one category where the trust question has no partial answer — and it is also the category where the declaration is least able to answer it. The rows you most want to read are not on this page at all: not one VPN below declares collecting location or web browsing, so both drop out of the grid entirely. That is the form's scope showing — it asks what the app collects from you, not what the tunnel carries on your behalf. What these declarations do describe is the account wrapped around the service — email address, purchase history, device identifiers, crash logs — and that varies noticeably from provider to provider. A no-logs claim is a separate artefact entirely. It lives in a privacy policy or an audit report, and Play never asks for it here.

What each developer declares their app collects and shares
Data categoryExpressVPNdeclares 4 collected, 0 sharedMullvad VPNdeclares 3 collected, 0 sharedNordVPNdeclares 5 collected, 0 sharedProton VPNdeclares 3 collected, 0 sharedSurfsharkdeclares 6 collected, 0 shared
Personal infoCollectedCollectedCollectedCollectedCollected
Financial infoNot declaredCollectedCollectedCollectedCollected
MessagesNot declaredNot declaredNot declaredNot declaredCollected
App activityCollectedNot declaredCollectedNot declaredCollected
App info & performanceCollectedCollectedCollectedCollectedCollected
Device or other IDsCollectedNot declaredCollectedNot declaredCollected
Declares data encrypted in transitYesYesYesYesYes
Declares you can request deletionYesYesYesYesYes
SourcePlay listingVerified 2026-08-07Play listingVerified 2026-08-07Play listingVerified 2026-08-07Play listingVerified 2026-08-07Play listingVerified 2026-08-07

Questions about VPNs

Why does no VPN declare collecting my browsing history or location?
Because Play's form asks what the app collects about you as a user, and traffic passing through a tunnel is not one of its fourteen categories. The absence of a web browsing row tells you nothing about whether connection logs are kept. That question is answered, if at all, by the provider's privacy policy and any independent audit of it.
Does a 'no-logs' policy show up in the data-safety declaration?
No. Data safety has no field for it, so a provider cannot state it there and its absence is not a red flag. Treat the declaration and the no-logs claim as two separate documents: the declaration covers account and diagnostic data, the policy covers the traffic.

We use cookies for ads and analytics.what this means.